πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1247 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ba0de040-5906-4a67-9306-7e6e65cca78f
< 7.5.1
MEDIUM 4.9 Absolute path traversal vulnerability in Font.php in the Font plugin before 7.5.1 for WordPress allows remote administra… wordfence
b972626c-6374-4084-a0e1-1ea4a3062228
< 2.33
MEDIUM 4.9 The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Directory Trave… wordfence
b95af878-f324-44ae-a4bf-0c1e994bb3c1
< 3.1
MEDIUM 4.9 The Askeet plugin for WordPress is vulnerable to SQL Injection via the 'sql_query' parameter in multiple AJAX actions (a… wordfence
b8440c1d-2a02-42b4-8fc5-42e5a107c0af
< 3.9.8
MEDIUM 4.9 The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulne… wordfence
b82a0f71-29d7-469a-8c69-5ab68d599cb9
< 2.2.3
MEDIUM 4.9 The Simple Download Counter plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2… wordfence
b809d705-a08f-45f2-8d4d-bc50ab89cc3a
< 7.0
MEDIUM 4.9 The SMS plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.9.12 due to insufficient… wordfence
b7850e73-8ffd-46d4-97c6-5343486a31dc
< 1.15.44
MEDIUM 4.9 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to gener… wordfence
b68a067f-91b0-413a-a164-c8d6a7c45d18
< 1.5.11
MEDIUM 4.9 The Product Labels For Woocommerce (Sale Badges) plugin for WordPress is vulnerable to SQL Injection in all versions up … wordfence
b6675c48-43d4-4394-a4a3-f753bdaa5c4e
< 1.1.8
MEDIUM 4.9 The PDF Generator For Fluent Forms – The Contact Form Plugin plugin for WordPress is vulnerable to Stored Cross-Site S… wordfence
b6364415-da02-4236-b635-d8fbd27faa33
< 5.8.2
MEDIUM 4.9 The Simple History plugin for WordPress is vulnerable to sensitive data exposure via Detective Mode due to improper sani… wordfence
b5635423-d17a-4f04-a164-64bf141b6bb4
< 3.43
MEDIUM 4.9 The IP Blacklist Cloud plugin for WordPress is vulnerable to Directory Traversal in versions before 3.43 via the importC… wordfence
b5582e89-83e6-4898-b9fe-09eddeb5f7ae
< 3.7.39
MEDIUM 4.9 WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploite… wordfence
b3fd57f3-f168-4a21-b6cd-f5214f047578
< 2.4.1
MEDIUM 4.9 The Infocob CRM Forms plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.4.0. … wordfence
b3a58e68-d1f1-4d4f-ac64-bc6cb7dbdbfc
< 2.4.4
MEDIUM 4.9 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the … wordfence
b3523535-6938-4922-8126-8386861ca512 MEDIUM 4.9 The GMAce plugin for WordPress is vulnerable to directory traversal in versions up to, and including, 1.5.2 via the 'gm-… wordfence
b31fcf67-61c7-43b2-a068-136b13965ca0 MEDIUM 4.9 The Contact Form 7 Round Robin Lead Distribution plugin for WordPress is vulnerable to SQL Injection in versions up to, … wordfence
b1978b8f-d207-44e5-8ec0-f2c047192d02
< 3.10.2
MEDIUM 4.9 The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to SQL Injection in all ver… wordfence
b0add190-5f7e-4153-9896-3584773fdd4c
< 2.6.7
MEDIUM 4.9 The YaySMTP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.6.6 due to insuffici… wordfence
b09d26ac-8f10-458f-8a97-8fdbdff4d833
< 3.4.4
MEDIUM 4.9 The Watu Quiz plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.4.3 due to insuffi… wordfence
b07c507e-9fab-426d-998e-ab557d1f1b1a
< 6.18.13
MEDIUM 4.9 The SeedProd Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.18.12 due to in… wordfence
af14ed79-f92d-4573-88ba-d2ef7b2e0a05
< 8.5.0
MEDIUM 4.9 The Element Pack Elementor Addons plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, … wordfence
ad2f240b-39b1-4fe9-9e49-1c88d2bfee38
< 2.0.15
MEDIUM 4.9 The Check & Log Email plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.0.14 due t… wordfence
ac9c676b-e15b-4052-9d93-e4185a49afe5 MEDIUM 4.9 The Neoforum plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 due to insufficie… wordfence
abd6eeac-0a7e-4762-809f-593cd85f303d
< 4.19.2
MEDIUM 4.9 The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Path Traversal in versio… wordfence
ab9f69ce-8589-47a8-80b1-6829c5a5bad1
< 6.4.7
MEDIUM 4.9 The Auto Affiliate Links plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 6.4.6… wordfence
← Prev 1244 1245 1246 1247 1248 1249 1250 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top